Do not report vulnerabilities, credentials, personal information, or client data in a public issue.
Use GitHub private vulnerability reporting when it is enabled. Otherwise,
contact contact@weiandata.com with the minimum information needed to begin a
private response. Include the affected component and version, impact, safe
reproduction steps, and a way to contact you. Do not attach real client data,
credentials, exploit data, or other restricted information.
The maintainers will acknowledge the report, assess severity and scope, coordinate remediation, and communicate release timing through a private channel. Response times depend on severity and repository maintenance status.
Before the first release, the repository owner must replace this table with the actual support policy. Security fixes are normally provided only for versions marked as supported.
| Version | Supported |
|---|---|
| Unreleased development branch | Yes |
| Earlier versions | No |
Give maintainers a reasonable opportunity to investigate and correct the issue before public disclosure. Minimize access and data collection during research, avoid service disruption, and preserve evidence without expanding exposure. Coordinated disclosure timing will reflect user risk and the availability of a verified fix.
The company-wide control baseline is defined by the WeianData Security Policy and Client Data Policy.